CWE-696 · 45 records
Incorrect Behavior Order
CVEs in this class
45 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-44108No exploit | Firewall bypass during shutdownphoenix contact · charx sec-3150 · CWE-696 | Critical9.3 | — | 0.8% | Jul 30, 2026 |
36Monitor | GHSA-j496-crgh-34mxNo exploit | ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooksGo · github.com/cosmos/ibc-go/v4 · CWE-696 | Critical9.1 | — | — | Apr 5, 2024 |
34Monitor | CVE-2026-45033Proof of concept | GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorgithub · copilot-cli · CWE-696 | High8.5 | — | 0.4% | May 13, 2026 |
32Monitor | CVE-2026-14169No exploit | ads-tec Industrial IT: Account lockout via non-atomic user creationads-tec industrial it · dvg-irf1401 · CWE-696 | High8.1 | — | 0.5% | Jul 28, 2026 |
32Monitor | CVE-2026-35386No exploit | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.openbsd · openssh · CWE-696 | High8.1 | — | 0.4% | Apr 2, 2026 |
30Monitor | CVE-2021-31379No exploit | Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.juniper · junos · CWE-696 | High7.5 | — | 1.3% | Oct 19, 2021 |
30Monitor | CVE-2025-31485No exploit | GraphQL grant on a property might be cached with different objectsapi-platform · core · CWE-696 | High7.5 | — | 0.6% | Apr 3, 2025 |
30Monitor | CVE-2025-48965No exploit | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL barm · mbed tls · CWE-696 | High7.5 | — | 0.5% | Jul 20, 2025 |
30Monitor | CVE-2026-41254No exploit | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplicalittlecms · little cms · CWE-696 | High7.5 | — | 0.4% | Apr 18, 2026 |
29Monitor | CVE-2023-33224No exploit | SolarWinds Platform Incorrect Behavior Order Vulnerabilitysolarwinds · solarwinds platform · CWE-696 | High7.2 | — | 2.8% | Jul 26, 2023 |
29Monitor | CVE-2024-24853No exploit | Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a priviCWE-696 | High7.3 | — | 0.2% | Aug 14, 2024 |
29Monitor | GHSA-p6j4-wvmc-vx2hNo exploit | Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is completenpm · openclaw · CWE-696 | High7.3 | — | — | Apr 10, 2026 |
28Monitor | CVE-2026-35636No exploit | OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolutionopenclaw · openclaw · CWE-696 | High7.1 | — | 0.5% | Apr 9, 2026 |
28Monitor | CVE-2026-73446No exploit | Security Advisory 0160arista networks · eos · CWE-696 | High7.0 | — | 0.3% | Sep 15, 2026 |
27Monitor | CVE-2026-35640No exploit | OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsingopenclaw · openclaw · CWE-696 | Medium6.9 | — | 0.8% | Apr 9, 2026 |
27Monitor | CVE-2026-35627No exploit | OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handlingopenclaw · openclaw · CWE-696 | Medium6.9 | — | 0.7% | Apr 9, 2026 |
27Monitor | CVE-2026-35652No exploit | OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatchopenclaw · openclaw · CWE-696 | Medium6.9 | — | 0.6% | Apr 10, 2026 |
27Monitor | CVE-2026-67217No exploit | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validationdavegamble · cjson · CWE-696 | Medium6.9 | — | 0.4% | Jul 29, 2026 |
27Monitor | CVE-2026-35637No exploit | OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DMopenclaw · openclaw · CWE-696 | Medium6.9 | — | 0.4% | Apr 9, 2026 |
27Monitor | CVE-2025-55114No exploit | BMC Control-M/Agent improper IP address filtering orderbmc · control-m/agent · CWE-696 | Medium6.9 | — | 0.4% | Sep 16, 2025 |
27Monitor | CVE-2025-9904No exploit | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Genercanon inc. · generic plus pcl6 printer driver · CWE-696 | Medium6.9 | — | 0.4% | Sep 28, 2025 |
27Monitor | CVE-2024-30410No exploit | Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.juniper · junos · CWE-696 | Medium6.9 | — | 0.4% | Apr 12, 2024 |
27Monitor | CVE-2024-30389No exploit | Junos OS: EX4300 Series: Firewall filter not blocking egress trafficjuniper · junos · CWE-696 | Medium6.9 | — | 0.4% | Apr 12, 2024 |
26Monitor | CVE-2026-44919No exploit | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///openstack · ironic · CWE-696 | Medium6.5 | — | 0.6% | May 13, 2026 |
26Monitor | CVE-2025-0150No exploit | Zoom Workplace Apps for iOS - Incorrect Behavior Orderzoom · meeting software development kit · CWE-696 | Medium6.5 | — | 0.5% | Mar 11, 2025 |
- CVE-2026-4410837Monitor
Firewall bypass during shutdown
CriticalCVSS 9.3No exploitEPSS 1%phoenix contact · charx sec-3150Jul 30, 2026
- GHSA-j496-crgh-34mx36Monitor
ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks
CriticalCVSS 9.1No exploitGo · github.com/cosmos/ibc-go/v4Apr 5, 2024
- CVE-2026-4503334Monitor
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
HighCVSS 8.5Proof of conceptEPSS 0%github · copilot-cliMay 13, 2026
- CVE-2026-1416932Monitor
ads-tec Industrial IT: Account lockout via non-atomic user creation
HighCVSS 8.1No exploitEPSS 1%ads-tec industrial it · dvg-irf1401Jul 28, 2026
- CVE-2026-3538632Monitor
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line.
HighCVSS 8.1No exploitEPSS 0%openbsd · opensshApr 2, 2026
- CVE-2021-3137930Monitor
Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
HighCVSS 7.5No exploitEPSS 1%juniper · junosOct 19, 2021
- CVE-2025-3148530Monitor
GraphQL grant on a property might be cached with different objects
HighCVSS 7.5No exploitEPSS 1%api-platform · coreApr 3, 2025
- CVE-2025-4896530Monitor
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL b
HighCVSS 7.5No exploitEPSS 1%arm · mbed tlsJul 20, 2025
- CVE-2026-4125430Monitor
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplica
HighCVSS 7.5No exploitEPSS 0%littlecms · little cmsApr 18, 2026
- CVE-2023-3322429Monitor
SolarWinds Platform Incorrect Behavior Order Vulnerability
HighCVSS 7.2No exploitEPSS 3%solarwinds · solarwinds platformJul 26, 2023
- CVE-2024-2485329Monitor
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privi
HighCVSS 7.3No exploitEPSS 0%Aug 14, 2024
- GHSA-p6j4-wvmc-vx2h29Monitor
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
HighCVSS 7.3No exploitnpm · openclawApr 10, 2026
- CVE-2026-3563628Monitor
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
HighCVSS 7.1No exploitEPSS 0%openclaw · openclawApr 9, 2026
- CVE-2026-7344628Monitor
Security Advisory 0160
HighCVSS 7.0No exploitEPSS 0%arista networks · eosSep 15, 2026
- CVE-2026-3564027Monitor
OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing
MediumCVSS 6.9No exploitEPSS 1%openclaw · openclawApr 9, 2026
- CVE-2026-3562727Monitor
OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
MediumCVSS 6.9No exploitEPSS 1%openclaw · openclawApr 9, 2026
- CVE-2026-3565227Monitor
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
MediumCVSS 6.9No exploitEPSS 1%openclaw · openclawApr 10, 2026
- CVE-2026-6721727Monitor
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
MediumCVSS 6.9No exploitEPSS 0%davegamble · cjsonJul 29, 2026
- CVE-2026-3563727Monitor
OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
MediumCVSS 6.9No exploitEPSS 0%openclaw · openclawApr 9, 2026
- CVE-2025-5511427Monitor
BMC Control-M/Agent improper IP address filtering order
MediumCVSS 6.9No exploitEPSS 0%bmc · control-m/agentSep 16, 2025
- CVE-2025-990427Monitor
Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Gener
MediumCVSS 6.9No exploitEPSS 0%canon inc. · generic plus pcl6 printer driverSep 28, 2025
- CVE-2024-3041027Monitor
Junos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.
MediumCVSS 6.9No exploitEPSS 0%juniper · junosApr 12, 2024
- CVE-2024-3038927Monitor
Junos OS: EX4300 Series: Firewall filter not blocking egress traffic
MediumCVSS 6.9No exploitEPSS 0%juniper · junosApr 12, 2024
- CVE-2026-4491926Monitor
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///
MediumCVSS 6.5No exploitEPSS 1%openstack · ironicMay 13, 2026
- CVE-2025-015026Monitor
Zoom Workplace Apps for iOS - Incorrect Behavior Order
MediumCVSS 6.5No exploitEPSS 0%zoom · meeting software development kitMar 11, 2025